Deepfakes and synthetic media of you
A deepfake is an image, video or audio clip made or altered with software so that it appears to show a real person doing or saying something they did not. If one depicts you, save evidence, report it to the platform, and use a hash-matching service if the content is intimate. In the US, covered platforms must remove non-consensual intimate imagery, including realistic computer-generated forgeries, within 48 hours of a valid request.
- Written by
- UltoPulto Editorial
- Published
- Last reviewed
General information, not legal advice. This page has not yet been reviewed by a lawyer; check the linked primary sources before relying on it.
Key takeaways
- Save the address, a screenshot and the date before you report anything.
- US federal law gives covered platforms 48 hours to act on a valid request to remove intimate imagery, including digital forgeries.
- StopNCII.org and NCMEC's Take It Down create a fingerprint of the image on your device. The file is not uploaded.
- Removing content from one site or from search results does not remove every copy.
What is the problem?
Synthetic media can place a real person's face, body or voice into content they never took part in. The harm that current law addresses most directly is intimate imagery made or shared without consent. US federal law calls a computer-generated intimate image of an identifiable person that is indistinguishable from an authentic one a digital forgery.
How does it happen?
The federal statute describes digital forgeries as created through software, machine learning or artificial intelligence. Once a file is posted it can be copied to other accounts and sites, which is why the US removal rule also requires platforms to make reasonable efforts to remove known identical copies.
It is also why hash-matching services exist. StopNCII.org creates a digital fingerprint of an image on your device, and participating platforms look for matches.
What laws may apply?
- United States, TAKE IT DOWN Act. The Act makes it unlawful to knowingly publish an intimate visual depiction or a digital forgery of an identifiable person without consent, with defined conditions and exceptions. Covered platforms had to set up a notice and removal process by 19 May 2026 and must remove reported content no later than 48 hours after a valid request. The Federal Trade Commission (FTC) enforces the platform duty.
- What a valid request includes. A signature, enough detail to find the content, a statement of good-faith belief that it is non-consensual, and your contact information.
- European Union. Article 50(4) of the AI Act, which applies from 2 August 2026, requires those who deploy an AI system to disclose that deepfake content has been artificially generated or manipulated. The duty is lighter for evidently artistic or satirical work.
- Scope. The US removal rule covers intimate imagery, not every deepfake. Other synthetic media may fall under platform rules or other laws, depending on where you live.
What you can do yourself
These steps are free and do not need UltoPulto.
- Save evidence first: the address of each post, screenshots, the account name and the date.
- Report the content with the platform's own reporting tool. For intimate imagery in the US, a valid request starts the 48-hour clock.
- If you were 18 or older in the image, use StopNCII.org. It accepts synthetic images of you, and the image does not leave your device.
- If you were under 18 in the image, use NCMEC's Take It Down. It is free and you can stay anonymous.
- Ask Google to remove fake explicit imagery of you from Search. The page itself stays online until the site removes it.
- If a US platform does not act on a valid request, complain to the FTC at TakeItDown.ftc.gov.
What UltoPulto can do
- Formal takedown notices to platforms for deepfakes, intimate images and impersonation, including the 48-hour duty under the US TAKE IT DOWN Act.
- Real delivery of notices. A notice is sent only to a contact our team has verified; until then it stays a draft.
- An evidence trail on every case: the notice, recipient, replies, deadline and status history.
- A follow-up after the deadline, then a regulator complaint draft for you to review and sign.
- Monitoring platforms for synthetic media of you. Today you report what you find and we send the notice.
- An exportable evidence dossier.
What UltoPulto cannot do
- Find every copy, or reach private chats and devices.
- Tell you whether a file is synthetic, or who made it. We do not offer deepfake detection.
- Make a platform comply. If a notice is refused or ignored, the case is marked refused or escalated.
- Stop someone generating new content, or remove you from an AI model that has already been trained. No service can do that.
Sources
- 147 U.S. Code § 223a: Notice and removal of nonconsensual intimate visual depictionsLegal Information Institute, Cornell Law School
- 247 U.S. Code § 223, subsection (h)Legal Information Institute, Cornell Law School
- 3FTC Begins Enforcing the TAKE IT DOWN ActFederal Trade Commission
- 4Frequently Asked QuestionsStopNCII.org (SWGfL)
- 5Take It DownNational Center for Missing & Exploited Children
- 6Article 50: Transparency Obligations for Providers and Deployers of Certain AI SystemsEU Artificial Intelligence Act text, Future of Life Institute
- 7Remove personal sexual content from Google SearchGoogle Search Help
Questions
Is it illegal to publish a deepfake of me?
It depends on the content and where you live. US federal law makes it unlawful to knowingly publish an intimate digital forgery of an identifiable person without consent, subject to conditions and exceptions.
How fast must a platform remove an intimate deepfake?
In the US, a covered platform must remove it as soon as possible and no later than 48 hours after receiving a valid request, and make reasonable efforts to remove known identical copies.
Can I use StopNCII.org for an AI-generated image?
Yes, if the image is of you, you have access to it, it is nude or semi-nude, and you were over 18 in it. StopNCII.org works only with its participating platforms.
Does removing a result from Google remove the content?
No. Google says the reported URL will no longer appear in its search results, but the content may still exist on the web.